CVE-2026-65919

HIGH

Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload

Title source: cna
STIX 2.1

Description

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or traversal sequences in the file parameter to read arbitrary files from the host filesystem without authentication.

References (5)

Core 5
Core References
Technical Description technical-description issue-tracking
Researcher Disclosure
https://github.com/meshery/meshery/issues/20076
Release Notes release-notes patch
Release Notes
https://github.com/meshery/meshery/releases/tag/v1.0.57
Issue Tracking issue-tracking patch
Pull Request
https://github.com/meshery/meshery/pull/20133

Scores

CVSS v3 7.5
EPSS 0.0061
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
meshery/meshery < 1.0.57
Published Jul 23, 2026
Tracked Since Jul 23, 2026